Hi,
It seems that would depend on how you are trying to capture the email address...
Are you using Wireshark on your desktop, and trying to capture your own email as it goes out?
Do you have a tap on a switch somewhere that is sniffing all traffic, and you want to just pull email traffic only?
You could probably start by filtering known email ports - 25, 110, etc.
It really depends on where you are at within your topology, and what kind of visibility you have to the email traffic passing through.
For example, you won't be able to pull email traffic out of a VPN tunnel by just having a hub stuck on the network somewhere - does that help?
Mike